7.5

CVE-2024-39745

IBM Sterling Connect:Direct Web Services information disclosure

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Sterling Connect Direct Web Services Version 6.0
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Ibm ≫ Sterling Connect Direct Web Services Version 6.1.0
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Ibm ≫ Sterling Connect Direct Web Services Version 6.2.0
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Ibm ≫ Sterling Connect Direct Web Services Version 6.3.0
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.223
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
IBM 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-327 Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.

https://exchange.xforce.ibmcloud.com/vulnerabilities/297312
Vendor Advisory
VDB Entry
https://www.ibm.com/support/pages/node/7166195
Vendor Advisory